VYPR
High severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026

Over-inclusive team membership expansion in GitHub App authentication provider for Rancher

CVE-2026-41053

Description

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/rancherGo
>= 2.14.0, < 2.14.22.14.2
github.com/rancher/rancherGo
>= 2.13.0, < 2.13.62.13.6
github.com/rancher/rancherGo
< 0.0.0-20260519172014-d0c047bbc6d20.0.0-20260519172014-d0c047bbc6d2

Affected products

2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.